Req #79324 [Com]: Alternative to safe_mode_protected_env_vars

From: Date: Sun, 01 Mar 2020 17:49:49 +0000
Subject: Req #79324 [Com]: Alternative to safe_mode_protected_env_vars
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225820@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79324&edit=1 ID: 79324 Comment by: diego dot blanco at treitos dot com Reported by: diego dot blanco at treitos dot com Summary: Alternative to safe_mode_protected_env_vars Status: Open Type: Feature/Change Request Package: Scripting Engine problem PHP Version: 7.4.3 Block user comment: N Private report: N New Comment: Thank you for your clarification Nikic. I just wanted to give more information about the problem so the implications are better understood. If you consider this is the right category, that is totally fine for me. Regarding disabling mail() for a secure setup, although I agree it would be safer, it is an expected feature for most of legit users so disabling it is not as an easy choice as disabling shell_exec(). For this reason it is usually enabled and the use of LD_PRELOAD to bypass restrictions is well known among web hackers (both white and black hats) Previous Comments: ------------------------------------------------------------------------ [2020-03-01 17:32:08] nikic@php.net To clarify, the "Security" category is for bugs that need to be kept private until the fix has been released. The classification change is not supposed to imply that there is no relation to security here, just that it doesn't need to be confidential. ------------------------------------------------------------------------ [2020-03-01 17:29:50] bugreports at gmail dot com when your setup is able to start a suid binary like sendmail and mail() is not disabled you have much more things to worry again: in a *sensibke* setup with security in mind there are nol libraries loaded and binaries executed at the runtime of a script, all the php extensions and tehir libraries are lareay loaded long before you can call setenv() ------------------------------------------------------------------------ [2020-03-01 17:22:56] diego dot blanco at treitos dot com You can use "strace" to see what external functions some PHP functions. For example the "mail" function calls "geteuid". So you can code a library that reimplements that function (i.e. "geteuid") and do whatever you want. Then you use LD_PRELOAD to load your custom library and then call the PHP function (i.e. "mail") so it will trigger your custom code. You have a good example here using these very same functions: https://github.com/0verl0ad/sifilis-PoC/ ------------------------------------------------------------------------ [2020-03-01 17:10:31] bugreports at gmail dot com and how is that user supposed to load any binary code in a sensible setup with dl() not enabled to begin with? LD_PRELOAD in the middle of the process is completly meaningless ------------------------------------------------------------------------ [2020-03-01 17:06:56] diego dot blanco at treitos dot com I see that the type was changed from Security to a "Feature Request". I am not saying that this change is wrong but I'd like to provide more information to describe why this has an important security impact. It is common to add some security measures when installing a PHP environment. Things like "open_basedir", "disable_functions", etc. This way if a website is compromised you can limit the impact in other websites or services in the same server. With the current PHP configuration options it is not possible to prevent users from setting environment variables like LD_PRELOAD. Due to this a user can upload a custom library and use LD_PRELOAD to execute code from that library that will effectively bypass any of the previous restrictions. In other words, a user that can execute custom PHP code can easily bypass restrictions like "open_basedir" or "disabled_functions" because systems administrators do not have a way to prevent users from setting LD_PRELOAD (other than disabling "putenv" function). I think this has a significant impact in security. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79324 -- Edit this bug report at https://bugs.php.net/bug.php?id=79324&edit=1

« previous php.bugs (#225820) next »